I have adopted the 2nd approach - every computer now has a range of defences.

I wanted to set up a single system to route the others thru & use that system to act as a firewall filter, IDS & logger. But until I can buy a cheap off the shelf machine that is better than my Buffalo Airport, I will use it as the front line, just wish I had more control of it such as I would have with a Linux system. (The Buffalo is obviously *nix based).

